Impact
Insufficient policy enforcement in Chrome DevTools allows a remote attacker who has already compromised the renderer process to serve a crafted HTML page that can escape the renderer sandbox. This vulnerability, identified as CWE‑693, provides a path for local code execution with the renderer’s privileges, compromising confidentiality, integrity, and availability of the host system.
Affected Systems
All desktop editions of Google Chrome on Windows, macOS, and Linux running a version older than 150.0.7871.47 are impacted.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe impact, yet the EPSS score of less than 1 % and the absence from CISA’s KEV catalog suggest limited exploitation in the wild. The attack requires a pre‑existing compromise of the renderer process; delivering a specially crafted HTML page via DevTools can trigger the sandbox escape, resulting in local code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA